Vulnerabilities/

SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory

Severity:
High

Description

A path traversal vulnerability in /api/chats/import allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into character_name.

Recommendation

Update the sillytavern package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
sillytavern
Anything's wrong? Let us know Last updated on April 06, 2026